Microsoft's lax security blasted by investigators after serious breach

Cascade of failings allowed Chinese hackers to access government emails, says US review board

John Leonard
clock • 3 min read
Microsoft's lax security blasted by investigators after serious breach

A damning report by the US Cyber Safety Review Board (CSRB), has revealed a "cascade of errors and security failures" at Microsoft which allowed a major breach of its systems last year.

The attack, which took place in summer 2023, saw China-linked threat actor Storm-0558 access the Microsoft Exchange Online mailboxes of 22 organisations and more than 500 individuals, including sev...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Asian Tech Roundup: Indian entrepreneurs call for 70-hour week

Legislation and Regulation

Plus: Australia cracks down on Big Tech

clock 12 July 2024 • 6 min read
Mammoth Microsoft Patch Tuesday fixes four zero-days, five critical bugs

Security

142 holes plugged this month

clock 10 July 2024 • 3 min read
Microsoft cuts more jobs, settles lawsuit

Corporate

The company acknowledged 'organisational and workforce adjustments' as a standard practice

clock 05 July 2024 • 3 min read

More on Security

'Gay furry hackers' breach conservative US think tank behind Project 2025

'Gay furry hackers' breach conservative US think tank behind Project 2025

Heritage Foundation calls group "degenerate perverts"

Tom Allen
clock 11 July 2024 • 2 min read
Why 'change' for the UK must include cybersecurity

Why 'change' for the UK must include cybersecurity

Labour needs to to get ahead and demonstrate a commitment to security from the outset

Rick Jones
clock 11 July 2024 • 4 min read
Mammoth Microsoft Patch Tuesday fixes four zero-days, five critical bugs

Mammoth Microsoft Patch Tuesday fixes four zero-days, five critical bugs

142 holes plugged this month

John Leonard
clock 10 July 2024 • 3 min read